Downtime costs more than prevention
A ransomware event takes an organization down for days, not hours. The cost of the outage, the restore and the recovery is almost always higher than the controls that would have prevented it.
Six failure points
Security is not a product but a set of specific things that go wrong, each answered by a control that sits somewhere particular. ILS Networks designs and builds that set — firewalls, segmentation, access control and endpoint protection.
Overview
ILS Networks designs, builds and operates the enterprise security estate: the firewall at the perimeter, internal segmentation, remote access and access control, and endpoint protection across workstations and servers. We also take over existing estates — mapping and documenting the policy already running before touching it, and only then taking on operations.
The work follows a fixed method: mapping before any change, maintenance windows the organization defines, a way back at every stage, acceptance testing and full documentation of what is handed over. That is how projects finish on the date that was set rather than drifting.
We are official partners of Fortinet, Sophos and Palo Alto Networks, and implement endpoint protection on ESET and SentinelOne. These are the platforms we work with most, not a closed list. If something else runs in your estate, we will design, build and maintain that too.
We work with organizations over years rather than over a single project — Ariston Group for around six years running the entire estate, Combe for more than fifteen, CooperVision and Galmarine for about five each.
Why invest in security
Security is measured on the bad day, not on an ordinary one. These are the practical differences between an estate that is protected and one that is relying on nothing happening.
A ransomware event takes an organization down for days, not hours. The cost of the outage, the restore and the recovery is almost always higher than the controls that would have prevented it.
Internal segmentation confines the damage to the area that was breached. Without it, one infected workstation gives access to everything on the same network.
Who is entitled, to what, and since when — documented and managed. Access opened "temporarily" two years ago is one of the most common gaps we find.
Most incidents start on an endpoint rather than at the firewall. Endpoint protection under one policy stops what has already passed the gate.
A documented configuration you can read and explain, instead of a rule list that accumulated. That is the difference between a change taking minutes and an investigation taking a day.
Monitoring and logging of what was blocked and who connected. Without it, there is no way after an incident to know what was touched and what was not.
The map
Six failure points we actually see in enterprise environments, and the control that answers each.
Ransomware arriving through an endpoint and encrypting whatever it can reach
On the endpoint and the server
An attacker with one foothold moving sideways into the rest of the estate
Between segments
Remote access opened for a specific need and left open afterwards
At the perimeter
A branch wired straight into the central network with no control of its own
At every site
Traffic leaving the organization for destinations nobody has checked
At the perimeter
Information-security requirements set by a customer, supplier or government body
Hardening, written policy and documentation you can present
Across the estate
The platforms
Each platform has its own page with the scope and the process. The choice follows the environment, the sites and the budget.
Proof
Ariston Group
Deployment of a Sophos-based security infrastructure with branch sites connected over Sophos RED — every location managed under a single, central security policy.
Combe
Sophos firewalls deployed alongside Arista switches — the security layer and the network layer designed and built as one system.
Prigat
An Arista-based core switching fabric built as the site's central communications infrastructure.
Galmarine
Deployment of Arista switches and an upgrade of the enterprise network infrastructure.
ILS Networks has been designing and operating enterprise networks and security infrastructure in Israel.
FAQ
We are official partners of Fortinet, Sophos and Palo Alto Networks at the firewall layer, and of ESET and SentinelOne at the endpoint. Working with several is deliberate: different environments suit different platforms, and we do not want the recommendation driven by what we happen to sell.
Segmentation divides the network into zones kept apart from each other, so reaching one does not automatically mean seeing the rest. It gets skipped because it is invisible — there is no box to buy and no dashboard proving it works. But it is the control that decides whether an incident stays local or becomes an organization-wide event.
A firewall handles the perimeter. It does not handle lateral movement inside the network, an endpoint infected by a file a user opened, or remote access that was opened and forgotten. Those are different controls sitting in different places — which is exactly what the map on this page shows.
Yes. In practice that is a combination of hardening the environment, written access policy and documentation you can present. At Combe we prepared the organization to meet information-security requirements set by government institutions. Requirements differ between bodies, so the work starts by mapping exactly what is being asked rather than assuming.
Yes, but that is a different layer with its own page. The network layer — core, Campus, wireless and site connectivity — is covered on the networking page. Here we focus on the security controls that sit on top of that network.
Yes. Ongoing monitoring, alert handling, version updates run as controlled changes, and coverage checking — which machines are not reporting. Support runs alongside the rest of the infrastructure, because a security incident does not wait for office hours.
Amendment 13 broadened the duties around protecting databases and the personal accountability of management. We are not legal advisers and we do not issue compliance certificates — but most of the requirements rest on infrastructure controls we do build: access control and permissions, network segmentation, encryption, documentation, monitoring, and backup you can actually restore from. The legal guidance itself should come from a qualified adviser.
We build and operate the infrastructure defence layers: firewalls, segmentation, VPN, access control, endpoint protection and EDR, and tested backup. What we do not do: we are not a 24/7 monitoring SOC, we do not run penetration tests, and we do not issue standards certifications. Where an organization needs those, we say so rather than take the work.
Not one tool but a combination: a firewall inspecting traffic, segmentation that prevents lateral spread, minimized privileges, behaviour-based endpoint protection, and backup with a copy that cannot be deleted from the compromised machine. The layer most often skipped is segmentation, and it is the one that decides whether an incident stays local or spreads.
Next step
A short technical call: what is installed today, which points on the map are already covered, and where the largest gap is. No commitment.
Thanks for contacting ILS Networks. We will come back to you shortly. If it is urgent, you can also call us directly.
+972-54-454-6020